FrontierStack iPhone & iPad Companion Manual home
Desktop Manual Mobile Manual 日本語 frontierstack.app ↗

iPhone & iPad Companion

FrontierStack

iPhone & iPad Companion

Watch your fleet, get push alerts, control services and reach device web UIs from your pocket — paired securely to the Mac.

Version 1.0.0 · First Edition · August 2026
Published by Enfour, Inc.

Table of Contents

Getting Connected
  1. 1Welcome to FrontierStack Mobile
  2. 2Pairing Your Device
  3. 3Security
  4. 4Staying Connected
Using FrontierStack Mobile
  1. 5Using the App: Fleet, Services, Shell & AI
  2. 6Settings, App Lock & Troubleshooting

Part I

I

Getting Connected

Pair your iPhone or iPad with the Mac, lock it down, and keep it reachable wherever you are.

1

Chapter 1

Welcome to FrontierStack Mobile

Your servers in your pocket — a secure remote control for the FrontierStack Mac app, so you can watch, get alerted, and act from anywhere.

FrontierStack for iPhone and iPad is a companion to the FrontierStack server-administration app that runs on your Mac. It is not a separate product you set up from scratch, and it does not run servers itself. It is a small, secure remote control for the Mac app — so the servers, agents and devices you manage from your desk are with you wherever you happen to be.

This short book is the manual for the mobile app only. The full desktop reference — everything the Mac app does, from the web stack to the AI Administrator — lives in the FrontierStack Manual. Here we cover just what you need to pair a phone or tablet, keep it safe, and use it day to day.

1.1What this app is

Think of the Mac app as the brain and this app as a trusted hand. The Mac is where FrontierStack lives: it talks to your servers over SSH, runs the AI Administrator, watches health, and holds your secrets. The mobile app talks only to that Mac, over a signed, encrypted connection. It never reaches out to your servers directly; it asks the Mac, and the Mac does the work.

That design keeps the mobile app simple and safe. There is no fleet to configure on your phone, no SSH keys to carry, no credentials to lose. Everything sensitive stays on the Mac. Your phone holds one private key — its own identity — and nothing more.

NoteThroughout this book, "the Mac" means the computer running the FrontierStack desktop app, and "this device" or "this app" means the iPhone or iPad in your hand. Each paired device is independent, with its own key and its own permission level.

1.2What you can do from your phone

The mobile app is a full remote for the desktop — the things you reach for when you are away from your desk, organised into five tabs:

  • Fleet. Every pinned server, the local Mac included, each with a status dot. Open one to control its services (start / stop / restart / reload), reboot it, run diagnostics, view logs, open its web UI, or reach Remote Tools and Fleet Run. Your pinned LAN devices sit below in collapsible sections.
  • Services. The Mac's services in collapsible sections, kept in sync with the desktop — anything you've hidden there doesn't show here.
  • Shell. A real command-line on the Mac or any server, logging in automatically with the Mac's stored credentials (never sent to the phone). Plus your saved and ready-made scripts.
  • AI. A multi-turn conversation with the AI Administrator, showing the tools it runs; read-only unless you switch on "Allow changes".
  • More. Push alerts, network Locations (switch sites), Fleet Run, temporary Shares, device web UIs, Settings and Help.

Some of these work from anywhere; others depend on your phone being able to reach the right network. We explain exactly which is which in Staying Connected.

screenshot to be added
Figure 1.1. The five tabs of FrontierStack Mobile on iPhone: Fleet, Services, Shell, AI and More.Capture: photograph an iPhone showing the app's Fleet tab, connected to a Mac with a couple of servers and a status dot each, the tab bar visible along the bottom

1.3Why it needs the Mac

This app does not work on its own — and that is deliberate. The Mac is the brain that talks to your servers, agents and devices. It holds the SSH connections to your fleet, the certificates, the secret vault, the alerting engine and the AI Administrator. Your phone is a secure window onto all of that.

Because the Mac does the real work, three things follow. The Mac must be running and reachable for the app to show live data or send a command. Push alerts are generated on the Mac (and its server agents) and relayed to your phone, so the Mac, or its push relay, needs to be online to notify you. And the permissions that govern what your phone may do are set on the Mac, not the phone — you stay in control from one place.

TipNo Mac yet? Install FrontierStack on your Mac first. This app has nothing to connect to until the desktop app is running and you have generated a pairing code. Visit frontierstack.app to get the Mac app.

1.4Install order

Getting set up takes three steps, in this order:

  1. Install FrontierStack on the Mac. Download and run the desktop app, and turn on its control server so it can accept connections from your devices. This is the foundation; nothing on the phone works without it.
  2. Install this app on your iPhone or iPad. Get FrontierStack Mobile from the App Store. On first launch it simply waits to be paired.
  3. Pair the two. On the Mac, generate a pairing QR code under the Paired Devices pane. In this app, scan it. From then on the two are linked, and your phone is enrolled with its own key.

The next chapter, Pairing Your Device, walks through that pairing in full.

SecurityA freshly paired device starts read-only — it can look but not change anything. You raise its permission level deliberately, on the Mac, and you can revoke any device instantly from the same place. Your phone never holds more power than you have granted it.

1.5How this manual is organised

This little book has two parts. Getting Connected — the part you are reading — covers this welcome, then pairing your device, the security model that keeps the link safe, and staying connected from home, over Tailscale, and away. Using FrontierStack Mobile then walks through the app itself: the tabs — Fleet, Services, Shell, AI and More — and finally settings and troubleshooting, including app lock and what to check when something will not connect.

1.6Platform requirements

FrontierStack Mobile is a universal app that runs on both iPhone and iPad, adapting its layout to each. It needs a reasonably current version of iOS or iPadOS; install it from the App Store, which will tell you if your device is supported. To do anything useful it also needs a Mac running the FrontierStack desktop app, reachable over your network, Tailscale, or a Cloudflare tunnel.

That is the whole picture: a Mac doing the work, a phone or tablet as your secure remote, and a signed link between them. When you are ready, turn to Pairing Your Device to begin.

2

Chapter 2

Pairing Your Device

Scan one QR code from the Mac and your iPhone or iPad enrols its own key — then the Mac decides exactly what it may do.

Pairing connects this app to FrontierStack running on your Mac. It takes one QR code and a few seconds. Behind that simplicity, the app enrols a private key that only ever lives on this device, so from then on the Mac can recognise — and trust — this exact phone or iPad. This chapter walks through pairing, approving a new device, and the permission levels that decide what it can do.

2.1How pairing works

Your Mac is the brain: it talks to your servers, agents and devices. This app is a secure remote control for it. Pairing is how the two recognise each other for good. When you scan the QR code, three things travel to the phone — the ways to reach your Mac (your home or office network, Tailscale, and a Cloudflare tunnel), a one-time token, and the Mac's certificate fingerprint so the connection can be pinned. The phone then generates its own key and enrols it with the Mac. After that first handshake the one-time token is spent; every later request is proven by the device's own key (see Security).

2.2Pairing step by step

  1. On your Mac, open FrontierStack → Paired Devices (in the Overview group).
  2. Click Pair a device. A QR code appears.
  3. In this app, tap Scan QR code and point the camera at the Mac's screen.
  4. The app reads the code, enrols its key, and connects. The new device appears in the list on the Mac.
screenshot to be added
Figure 2.1. The Mac shows a pairing QR code in the Paired Devices pane while the iPhone's scanner frames it.Capture: photograph the Mac's "Pair a device" QR sheet next to the iPhone showing the Scan QR code camera view
TipKeep the phone close to the screen and steady. If the camera will not focus, raise the Mac's display brightness and fill the frame with the code.

Can't reach the Mac? Pair over Bluetooth. On a locked-down Wi-Fi network — guest networks, client isolation, a captive portal — the app may read the QR fine but fail to connect. If the Mac has Allow Bluetooth pairing turned on (in its Paired Devices pane) and you are within a few metres of it, tap Pair over Bluetooth and enrolment finishes over a short-range Bluetooth link instead. It uses the same one-time QR code and the same signed handshake — only the transport changes — so the result is identical to pairing over the network. The Mac only advertises over Bluetooth while its Pair dialog is open.

2.3What the QR code carries

The QR is not just a token — it is everything the app needs to reach your Mac safely:

  • Reach paths — the addresses for your home/office network, Tailscale, and any Cloudflare tunnel, so the app can find the Mac whether you are home or away (Staying Connected).
  • A one-time token — used only for the initial enrolment, then discarded.
  • The certificate fingerprint — lets the app pin the Mac's HTTPS certificate, so the connection cannot be intercepted even though the certificate is self-signed.

2.4Approving the new device

A freshly paired device starts read-only — it can see status and alerts but cannot change anything until you say so. On the Mac, in the Paired Devices pane, each device is listed by name with a key fingerprint and a last-seen time. There you raise its permission level, rename it, or revoke it.

SecurityEvery device has its own key. Revoking one on the Mac cuts it off instantly and does not affect any other paired device. If a phone is lost, revoke it here.

2.5Permission levels

The Mac decides how much each device may do. Set the level on the Mac in the Paired Devices pane (Overview group).

LevelWhat this device can do
Read-onlySee status, alerts, logs and device pages. No changes.
RestartRead-only, plus start / stop / restart services.
OperateRestart, plus fleet operations.
Full controlEverything, including tools, scripts and opening shares.

If a button is disabled or an action is refused, this device's level does not allow it — raise it on the Mac, or use a device that already has the rights.

TipKeep a phone you carry everywhere at a low level (Read-only or Restart), and reserve Full control for one trusted device. You lose nothing day to day and limit what a lost phone could do.
Pair more than one device
Pair as many iPhones and iPads as you like — each enrols its own key and gets its own level. A wall-mounted iPad might sit at Read-only as a status display, while your main phone has Restart for quick fixes on the go.

With the device paired and its level set, you are ready to use the app. Connectivity from home and away is covered next in Staying Connected, and the day-to-day tabs in Using the App.

3

Chapter 3

Security

Why it is safe to control your Mac from your pocket — even over the open internet. Signed requests, pinned encryption, an app lock, and instant revocation if a phone is lost.

This app can start and stop real services on a real Mac, sometimes from the other side of the world. That only makes sense if a stolen phone, a sniffed network or a guessed token can't be turned into control of your servers. FrontierStack is built so that none of those, on their own, is enough. This chapter explains the layers — and why they let you reach your Mac safely through a Cloudflare tunnel from anywhere.

3.1Every request is signed

The strongest protection is invisible. When this device was paired, it generated its own private key and stored it in the iOS Keychain — it never leaves the phone, and even this app cannot read it back out as plain text. Every request the app sends to your Mac is signed with that key. The Mac keeps an allow-list of the devices you approved, each by its public key, and checks the signature on every request against the device that claims to be sending it.

This is the FS1 per-device model: it uses Ed25519 signatures, and each signed request also carries a timestamp and a one-time nonce, so a captured request can't be replayed even seconds later. The practical consequence is the important part: a bearer token on its own — the kind of shared secret that older apps rely on — cannot control anything here. Without this device's private key, a copied token is inert.

SecurityBecause control is bound to a key the Mac has explicitly approved, adding a new phone is a deliberate act on the Mac, not something a leaked password can do. A request signed by an unknown key is simply refused.
screenshot to be added
Figure 3.1. The Mac's Paired Devices pane (in the Overview group): each phone shown by name, key fingerprint and last-seen time.Capture: photograph the Mac app's Paired Devices pane with two devices listed, scope pickers and a Revoke button visible

3.2Encrypted, pinned connections

Signatures prove who is talking; encryption protects what they say. When your Mac advertises an HTTPS address, this app talks to it over TLS like any secure connection. But there is a twist: the Mac uses a self-signed certificate it generates itself, so there is no public authority to vouch for it.

Instead, the app uses certificate pinning. The pairing QR code carried the exact fingerprint of the Mac's certificate. From then on, the app accepts only a connection presenting that exact certificate — nothing else. An attacker who sits in the middle and offers their own certificate, even a "valid" one, is rejected, because its fingerprint won't match the one you pinned at pairing.

SecurityPinning is what makes a self-signed certificate trustworthy here. A normal browser would warn you about it; this app has something a browser doesn't — the one fingerprint it is allowed to see — so it can be both private and certain, with no certificate authority involved.

3.3Why this is safe from anywhere

Put the two together and you can see why reaching your Mac over a public path — a Cloudflare tunnel, for instance — is safe rather than reckless. The tunnel only carries traffic; it can't forge it.

  • The connection is encrypted and pinned, so the tunnel (and anyone along the way) sees ciphertext to a certificate they can't impersonate.
  • Every request is signed by this device's key, so even something that reached the Mac couldn't issue a command it would honour.
  • Replay is blocked by the per-request timestamp and nonce, so re-sending a captured request fails.

The Mac decides whether the public path even exists, and you can close it. Nothing here depends on the network being private — the protections travel with each request.

3.4App lock

Network security can't help if someone simply picks up your unlocked phone. The app lock closes that gap. In Settings, turn on a passcode; from then on the app is locked until you enter it, and you can add Face ID or Touch ID for one-tap unlock. The app re-locks whenever you leave it — switch apps or lock the phone, and it asks again on your return.

The passcode itself is never stored. The app keeps only a salted hash of it in the device Keychain, so even with the phone in hand there is no passcode to read back — an attempt either hashes to the stored value or it doesn't. Biometric unlock is handled by iOS, which only tells the app yes or no.

Mirroring the Mac's lock. If the Mac itself has an App Lock password, this app adopts it at pairing: it locks and requires the same password. The password never travels — only its salted hash is delivered over the pinned pairing connection, and the phone verifies your entry against it locally (the identical scheme both use). While mirrored you can't change or remove the lock from the phone; it follows the Mac.

NoteThe app lock is separate from the Mac's own lock state. Unlocking the app lets you use it; whether the Mac is unlocked still governs which controls are live, as covered in Control.

3.5What this device is allowed to do

Authentication answers "is this really my phone?"; permission scopes answer "and how much may it do?". That decision lives on the Mac, not here. Each paired device is assigned one of four levels — Read-only, Restart, Operate or Full control — and the Mac enforces it on every signed request. A phone you carry everywhere can stay safely at a low level even though it is fully paired.

If a button is disabled or an action is refused, this device's level doesn't permit it — raise it on the Mac, or use a device that already has the rights. The four levels and what each unlocks are set out in Pairing.

Two grants sit alongside the level, both set on the Mac. Allow AI Administrator (on by default) decides whether this phone may use the AI tab at all — a way to let one device chat while blocking another. Allow remote shell is offered only at Full control and is off by default; it is what lets this device open the Shell tab and reach your servers directly. Neither is a bypass: even with AI allowed, any change still needs Full control's "Allow changes" and the app unlocked.

3.6If you lose a device

Because each phone has its own key, you never have to change anything else to cut one off. On the Mac, open Paired Devices (in the Overview group), find the device by name, and revoke it. Its key is removed from the allow-list at once: the moment it tries to talk to the Mac again, its signature is rejected. Your other devices are untouched and keep working.

Revoking on the Mac is the authoritative step — it stops the device even if you can't reach the phone itself. "Unpair this device" inside the app only forgets the connection on a phone you still hold; for a lost one, revoke on the Mac.

For a phone that is genuinely gone, the Mac offers a stronger one-click action: Secure lost phone. Beyond revoking the key, it immediately cancels the device's older queued actions, closes its open sessions, removes any SSH keys it installed on your servers for direct access, and deactivates its push notifications. Servers that are offline at that moment stay listed so you can finish removing the keys when they come back.

TipLost or stolen phone? Don't wait to find it. Open the Mac, go to Paired Devices (in the Overview group), and use Secure lost phone on that device — it is cut off instantly, its server access is stripped, and your other devices are unaffected.
4

Chapter 4

Staying Connected

How the app finds your Mac wherever you are — same Wi-Fi, Tailscale, or a Cloudflare tunnel — and what the little coloured dot is telling you.

After you pair, the phone never asks you to type an address. It already knows several ways to reach your Mac — captured the moment you scanned the QR code — and it quietly tries them in order until one answers. This chapter explains that order, why away-from-home access sometimes needs a little help, and how to read the connection status at a glance.

The whole connection is anchored to your Mac's control server. If that server is switched off, or the Mac is asleep or off the network, there is nothing for the app to reach — so this chapter ends with the conditions that have to be true for any of it to work. For pairing itself, see Chapter 3; for the desktop side of the control server, see the desktop manual.

4.1The three paths home

When you paired, the QR code carried more than a token: it carried a small list of addresses at which your Mac can be found — its address on your home or office network, its Tailscale address, and the address of any Cloudflare tunnel the Mac has enabled. The app keeps that list and, every time it needs to talk to the Mac, walks it in a fixed order:

  1. Your home or office network first. If the phone and the Mac are on the same Wi-Fi (or wired LAN), the app connects directly — the fastest, lowest-latency path, with nothing in between.
  2. Tailscale next. If a direct connection doesn't answer, the app tries the Mac's Tailscale address. This works wherever you are, as long as your phone and Mac are members of the same tailnet.
  3. A Cloudflare tunnel last. If neither of those works, the app falls back to a Cloudflare tunnel — but only if the Mac has one enabled. This reaches your Mac from anywhere without any network of your own.

The app remembers which path last worked and tries that one first next time, so reconnecting on a familiar network is near-instant. You never choose the path by hand; you simply open the app and it lands on whichever route is live.

screenshot to be added
Figure 4.1. The Fleet tab header showing the connection status dot and the Mac's name; pull-to-refresh in progress.Capture: capture the Fleet tab at the top, status dot green/"connected", mid pull-to-refresh so the spinner is visible

4.2When you're on the same Wi-Fi

At home or in the office — phone and Mac on the same network — the app takes the direct path. This is the best case: everything is reachable and fast. Service status, start and stop, alerts, the AI, device web UIs and LAN shares all behave as if the phone were sitting next to the Mac, because in network terms it is.

If your Mac advertises an HTTPS address, the app verifies the Mac's identity using the certificate fingerprint it captured at pairing, so even a self-signed certificate can't be impersonated on your own network.

4.3When you're away from home

The moment you leave your network, the direct path stops answering and the app moves on to the other two. Away access comes down to a simple question: can your phone reach your Mac at all right now?

  • Tailscale answers yes whenever your phone and Mac share a tailnet. It is the most reliable away path: it works on cellular, on hotel and café Wi-Fi, behind almost any router, with no ports to open.
  • A Cloudflare tunnel answers yes whenever the Mac has one running. It needs nothing on the phone and reaches from anywhere, but it depends entirely on the Mac keeping that tunnel up.

If neither is available — no shared tailnet, no tunnel — the app simply can't see your Mac from outside, and the status dot goes to offline. That is expected behaviour, not a fault: a Mac on a private home network is, by design, not reachable from the open internet.

TipFor dependable access away from home, install Tailscale on both your phone and your Mac (or on a router that fronts your Mac). Once both are signed in to the same tailnet, everything — the Mac and the devices behind it — is reachable as if you were home, with no ports to forward and nothing exposed to the public internet.

4.4Device web UIs and LAN shares

Reaching your Mac is only half the story. The Web UIs page (under More) opens the web interfaces of other things on your network — routers, NAS boxes, printers, dashboards — and Shared (under More) can open LAN shares your Mac has temporarily exposed. These live on the network itself, not on your Mac, so the app reaching your Mac does not guarantee it can reach them.

A device web UI or a LAN share is reachable only when your phone can actually get onto that network:

  • On the same Wi-Fi — everything on the LAN is directly reachable.
  • Over Tailscale — reachable if your tailnet routes to that network, for example through a subnet router advertising the LAN's range. Without that, Tailscale gets you to the Mac but not to the printer beside it.

This is the practical reason the TIP above recommends a subnet router or a Tailscale-connected router: it turns "I can reach my Mac" into "I can reach my whole network," which is what makes the Web UIs and Shared screens useful from the road.

NoteA LAN share's reach also depends on how the Mac opened it. A Cloudflare tunnel or Tailscale funnel share works from anywhere; a plain LAN forwarder works only on the same Wi-Fi; a Tailscale serve share works across your tailnet. Shared reflects this per share.

4.5The connection status dot

The coloured dot in the Fleet tab header is the app's honest summary of whether it can talk to your Mac right now. It has three states:

StateWhat it means
ConnectedThe app reached your Mac on one of the three paths and is showing live data. Service controls work to the extent your device's access level allows.
ConnectingThe app is trying the paths in order. This is normal for a moment after launch, after a network change, or after a pull-to-refresh.
OfflineNo path answered. The Mac is asleep, off, or unreachable from where you are — or its control server is off. The app shows the last data it had, clearly marked stale.

To force a fresh attempt, pull down to refresh on the Fleet tab. The dot returns to connecting while the app re-walks the path list, then settles on connected or offline. Pull-to-refresh is also the first thing to try whenever something looks stuck or out of date.

4.6What has to be true

None of the three paths can conjure a connection that isn't there. For the app to reach your Mac, all of the following must hold:

  • The Mac's control server is enabled. This is the service the phone talks to. If it's switched off on the Mac, every path fails and the dot stays offline.
  • The Mac is online and reachable. It must be awake, on a network, and reachable from where your phone is — same Wi-Fi, shared tailnet, or via its Cloudflare tunnel. A sleeping Mac answers nothing; consider keeping it from sleeping if you rely on remote access.
  • You have a working away path, if you're away. Off your home network, that means Tailscale on both ends, or a tunnel the Mac keeps running.

Push notifications follow the same logic from the other direction: the Mac (or its push relay) must be online to send an alert. If alerts go quiet, the cause is usually the same as a missing connection — the Mac is asleep, off, or unreachable. The summary below ties the three locations together.

Where you areHow it connectsWhat's reachable
Same Wi-Fi / LAN as the MacDirect, over your networkEverything: Mac, services, AI, device web UIs, LAN shares
Away, shared tailnetTailscaleThe Mac and the AI; devices and LAN shares too if a subnet router routes to that network
Away, Cloudflare tunnel onlyCloudflare tunnel (Mac-enabled)The Mac and the AI; device UIs only if otherwise reachable
Away, no Tailscale and no tunnel— (no path)Nothing live; offline, last-known data only

Part II

II

Using FrontierStack Mobile

The five tabs you live in day to day — your fleet, its services, a shell, the AI Administrator, and everything else under More.

5

Chapter 5

Using the App: Fleet, Services, Shell & AI

Once your phone is paired, the app is a full remote for the desktop. This chapter walks through the five tabs — what each shows and what it lets you do.

FrontierStack for iPhone and iPad is a full remote for the FrontierStack app on your Mac. Its main screen is a row of five tabs — Fleet, Services, Shell, AI and More. Each is a window onto something the Mac already does, sent to your phone over the secure, signed connection you set up when you paired. This chapter covers all five; Settings and the lock screen are in the next chapter, and pairing itself is in Pairing your device.

Two ideas run through every tab. First, the Mac is the brain: your phone shows and steers what the Mac sees and does, so when the Mac is offline the tabs go quiet. Second, what you are allowed to do depends on this device's permission level, which you set on the Mac — and the most powerful things (a raw shell, letting the AI make changes) need extra grants, described where they come up.

5.1Fleet — your servers and devices

The Fleet tab is home. At the top, Phone & Fleet keeps two independent facts apart: the route this phone is using to reach the Mac, and the Fleet site the Mac currently uses to scope monitoring and devices. Below it are two groups: your servers and your pinned devices.

The Servers section lists every pinned server — the local Mac is just the first row, so you drive it exactly like any other. Each row carries a status dot:

DotMeaning
GreenUp — reachable and healthy.
Amber triangleDegraded — reachable but something needs attention.
RedDown — the Mac can't reach it right now.
HollowUnknown — not yet probed.

Tap a server to open it. Its detail screen gives you the same host-level controls as the desktop:

  • Services — start, stop, restart or reload each detected service.
  • Reboot, Run Diagnostics (a plain-language "what's wrong right now") and View Logs.
  • Open Web UI in the built-in browser, and Open Shell (jumps to a shell bound to this server).
  • Remote Tools — ping, traceroute, listening ports, a web check and a log tail, run on the server itself.
  • Fleet Run — one operation across every server at once (see More, below).

Below the servers, your pinned devices appear in collapsible sections by kind — routers, switches, printers, NAS, smart-home and so on — each with an online/offline dot and a menu to open its web UI, check its status, or power-cycle it (where a plug or KVM is linked on the Mac).

screenshot to be added
Figure 5.1. The Fleet tab: a location banner, a Servers list with the Mac first and a status dot on each row, and collapsible device sections below.Capture: capture: Fleet tab connected, two or three servers each with a green/amber dot, one collapsible device group expanded
NoteFleet is a live mirror, not a cache. A red dot or an "offline" state means the phone (or the Mac) genuinely can't reach that host right now — check that the Mac is running and that you are on the same Wi-Fi, the same Tailnet, or that a Cloudflare tunnel is up.

5.2Services — live state, independent of the Mac's sidebar

Service state and controls live on the Operations tab, which shows what is actually running right now and lets you start, stop, restart and reload what your device is permitted to touch.

This app is independent of the Mac's sidebar. Whatever you have hidden from the sidebar on the desktop — to keep that window tidy — is still reachable here. The two interfaces are for different situations: at your desk you curate what you look at all day; on the road you want to reach whatever has broken. Nothing you do on the phone changes what the Mac shows, and nothing hidden on the Mac is withheld from the phone.

NoteEarlier versions let the phone edit the Mac's sidebar. That was removed: it made the phone's usefulness depend on a cosmetic desktop preference, which is exactly the wrong coupling when you are away from the Mac and something is down.

5.3Shell — a real command line

The Shell tab opens a command-line on the Mac or any linked server. Pick the target from the bar at the top — This Mac or any server — then type commands and read their output. Servers log in automatically using the key and credentials already stored on your Mac; a sudo command uses the server's saved sudo password. None of those credentials ever travel to your phone — the Mac runs the command and streams the output back.

Under More → Scripts you'll find your saved scripts and the built-in maintenance presets, synced from the Mac; tap one to run it and watch the output stream in.

Direct SSH — when the Mac is offline. The shell above is routed through the Mac. On a server's page you can also tap Enable direct SSH (while the Mac is online) to install this device's own SSH key on that server; after that, SSH (direct) opens a real terminal straight from the phone to the server — even when the Mac is offline or on another network — as long as you can reach the server's network (same Wi-Fi or over Tailscale). The phone's SSH key is generated on and never leaves the phone, and the Mac's own key and passwords are never copied to it. Revoking or unpairing the device removes its key from your servers.

SecurityThe shell is the most powerful thing the app can do, so it is gated tightly. This device must be at Full control with "Allow remote shell" switched on for it in the Mac's Paired Devices pane, the Mac must be unlocked, and every request is signed. Without that explicit grant the shell stays off — "Full control" alone is not enough.
NoteThe shell is line-oriented with a working directory that persists across commands (so cd sticks). It runs ordinary commands and scripts; full-screen terminal programs like top or vim aren't supported.

5.4AI — chat with the Administrator

The AI tab is a multi-turn conversation with the same AI Administrator that runs on your Mac. Ask about your servers, services or devices in plain language; as it works it shows the tools it runs and their results inline, so you can see how it reached an answer.

By default the assistant is read-only — it can look but not change. Switch on "Allow changes" (top-right) to let it act: restart a service, flush DNS, and so on. The conversation history — including any tool results, which can contain secrets — stays on the Mac; your phone only sees the rendered replies. Everything the AI does here still runs on the Mac and obeys the same guards as on the desktop; a chat from the phone can be turned off entirely per device with the Mac's Allow AI Administrator switch, and it always requires the app unlocked and this device signed. Conversations you have from the phone are saved into the Mac's AI Administrator history, so you can pick them back up there.

NoteIf a change is refused with “needs approval”. By default FrontierStack asks you to confirm each external change in the app on the Mac — which you obviously can't do while holding the phone. Approve this device once instead: on the Mac, Paired Devices ▸ your device ▸ “Allow AI changes without asking me here”. That waives only the confirmation prompt: the device still needs a permission level that allows tools, the Mac still has to be unlocked, Allow changes still has to be on for that conversation, and if you require a password for external changes that is still enforced.

A green shield to the left of each reply means the answer was protected: before anything left your Mac for the AI model, FrontierStack scrubbed secrets (keys, tokens, passwords) from the tool results — tap the shield to read what that means. You can select and copy both your questions and the replies (press and hold, or use the Copy action) to paste an answer elsewhere. And when you have a server selected, the assistant answers about that machine — the query still runs on your Mac, but "how long has it been up?" or "what's listening?" is scoped to the device you picked, not the Mac.

screenshot to be added
Figure 5.2. The AI tab mid-conversation: a question, the assistant's reply with a green protection shield beside it, and an inline "ran read_logs" tool line, with the Allow changes toggle in the top-right.Capture: capture: AI chat showing one exchange with the green shield, a visible tool action and the Allow changes toggle

5.5More — alerts, locations and the rest

The More tab gathers everything that doesn't need its own tab.

5.5.1Queue Operations

Queue Operations mirrors the Mac's read-only queue dashboard. Pull to refresh health for RabbitMQ, Kafka, NATS/JetStream, Redpanda, AWS SQS, Azure Service Bus, Google Pub/Sub, Celery, Redis Streams, Pulsar and RocketMQ. It shows backlog, consumers, lag and dead-letter totals without downloading message bodies. Configure credentials and thresholds on the Mac; the phone receives only the signed, sanitised health summary.

5.5.2Alerts

Alerts is the inbox of server alerts — a service down, a disk filling, a certificate expiring — raised by the Mac and its agents. Tap Enable push notifications so they reach you even when the app is closed. Push needs the Mac (or its relay) online to send.

SecurityYour phone never registers itself with the push server directly. When you enable notifications it hands its push token to the paired Mac over the signed connection; the Mac signs the registration with the key from its active licence and registers it for you. So revoking the phone on the Mac — or unpairing here — also stops its push notifications, even while the phone is offline.

5.5.3Checks — watchdogs and a maintenance pause

Checks is the manager for the Mac's Service Guardian: every service being guarded, whether each is healthy, and which have Keep Alive or Auto Recover switched on. It is the phone-side view of the pane described in Chapter 11 of the desktop manual.

Its useful trick is the pause. Before working on a machine, pause all checks — or just one service — for anything from 15 minutes to a day. While paused, the Mac stops health-checking and stops restarting that service, so your maintenance doesn't fight the watchdog or set off alerts.

Disk repair is protected automatically: while Disk Utility First Aid or a filesystem repair tool is running, automatic recovery pauses without changing its settings. Maintenance-timeout counters are cleared, and recovery waits 60 seconds after repair finishes before starting fresh. The Checks screen shows this safety hold.

TipPausing is deliberately not the same as switching a watchdog off. Nothing is disabled and no setting is lost: the check resumes by itself, exactly as configured, when the window ends. You can also resume early. That is the whole point — you cannot forget to turn protection back on.

5.5.4Phone connection & Fleet sites

Phone & Fleet Sites separates three things that the old “Location” label could make look like one: how this iPhone reaches the Mac, the site the Mac matches from its own network, and the Fleet site currently used to scope monitoring and devices. The phone's physical position and network do not select the Fleet site.

Choose Follow Mac's detected site to let the Fleet context follow the Mac. Pin another Fleet site when you deliberately want to view or operate that site's context. Pinning does not change the phone's route to the Mac and does not make a remote private network reachable; opening devices at that site still needs an existing route such as Tailscale or a VPN.

5.5.5Fleet Run, Shared & web UIs

Fleet Run runs one operation across every server at once — update packages, restart a service, check disk or uptime — and shows the per-host results. Shared lists the temporary Debug Shares the Mac has opened (a localhost dev site exposed via a tunnel), which you can open or stop; opening a new one needs Full control and "Allow changes" on the Mac. Web UIs & Bookmarks opens the admin pages of your routers, NAS and cameras in a built-in browser that trusts self-signed LAN certificates, plus any addresses you bookmark on the phone.

Note"Reachable" means your phone is on the device's network — true on the same Wi-Fi, and often true away from home over Tailscale (for example through a subnet router). If a device page won't load it is almost always a reachability problem, not the app: the browser already trusts the certificate.

Finally, More holds Settings and Help — covered next.

6

Chapter 6

Settings, App Lock & Troubleshooting

Lock the app to your face or a passcode, unpair cleanly when a phone changes hands, and fix the handful of things that can go quiet between phone and Mac.

The Settings screen — under the More tab — is where you protect this device and tidy up after it. It has three jobs: lock the app behind a passcode or Face ID, manage the connection to your Mac, and hand you the controls to unpair when a phone moves on. This final chapter walks through each, then ends with a plain symptom-and-fix table for the few times the link between your phone and your Mac goes quiet.

6.1A tour of Settings

Open More → Settings. It is a single scrolling form, grouped into sections:

  • App Lock — the passcode and biometric unlock for this app.
  • Notifications — the current push status and an Enable notifications button if you have not allowed them yet.
  • Connection — which Mac you are paired to, the address you are currently reaching it through, this device's key, and Unpair this device.
  • Help & Guide and About — the in-app guide that mirrors this manual, and version information.

Everything that follows lives in one of those sections. None of it changes anything on the Mac; these settings are about this phone or tablet only.

6.2App Lock: a passcode for the app

FrontierStack Mobile is a remote control for real servers, so it is worth a lock of its own — separate from your device passcode. In App Lock, turn on Require passcode to open. You are asked to set a passcode (four digits or more) and confirm it. From then on the app launches locked: a full-screen gate asks you to Enter your passcode before it shows anything.

The app re-locks whenever you leave it — switch to another app, lock the phone, or send FrontierStack to the background — so a glance over your shoulder never exposes your fleet. To change the code later, tap Change passcode (you enter the current one first). To remove it, switch the toggle off and confirm with the current passcode.

screenshot to be added
Figure 6.1. The App Lock section of Settings: the "Require passcode to open" toggle, "Change passcode", and the "Unlock with Face ID" switch.Capture: capture: Settings tab scrolled to the App Lock section with a passcode already set, so Change passcode and the biometric toggle are visible
SecurityYour passcode is never stored. The app keeps only a per-install salted SHA-256 hash of it in the device Keychain, and verifies attempts against that hash. There is no way to read the passcode back — if you forget it, remove and re-set it, or unpair and pair again.

6.3Face ID and Touch ID

Once a passcode is set, and if your device offers biometrics, an extra switch appears: Unlock with Face ID (or Unlock with Touch ID, matching your hardware). Turn it on and the lock screen offers biometric unlock the moment it appears — you rarely type the passcode at all. The passcode stays as the fallback for when a face or finger is not recognised.

Biometric unlock is a convenience layered on top of the passcode, not a replacement for it: you must set a passcode first, and removing the passcode turns biometrics off automatically. If your device has no Face ID or Touch ID, the switch simply does not appear and the passcode is the only gate.

TipA phone you carry everywhere is the natural place for Face ID: the app unlocks the instant you look at it, yet stays sealed to anyone else. Pair that with a low permission level on the Mac (see Permission levels, earlier in this part) and a lost phone is harmless.

6.4Unpairing this device

When you sell a phone, hand one to someone else, or simply want to start the connection over, use Unpair this device in the Connection section. You are asked to confirm; on confirmation the app forgets the pairing — the Mac's addresses, the pinned certificate, and this device's signing key — and returns to the pairing screen. To reconnect, scan the QR code from the Mac again.

Unpairing is the right first step, but it only clears this phone. The Mac still lists the device as paired until you remove it there. For a phone that is lost or no longer yours, do both.

SecurityUnpairing on the phone forgets the connection locally; it does not revoke this device on the Mac. For full security — especially a lost device — open FrontierStack on the Mac and go to the Paired Devices pane, find this device by name, and revoke it. Revoking there invalidates its signing key instantly, so even someone holding the phone can no longer reach your servers.

6.5Troubleshooting

Most trouble is connectivity: the phone and the Mac can't find each other, or a control is greyed out because of where things stand on the Mac. Work down the table, then read the notes below it.

SymptomLikely causeFix
Can't reach the Mac — the dot is offline or the Fleet tab is emptyThe Mac's control server isn't running or isn't reachable from where you areCheck FrontierStack is open on the Mac with its control server enabled; confirm you are on the same Wi-Fi, or that Tailscale is connected on both ends, or a Cloudflare tunnel is enabled; then pull down to refresh.
Controls are greyed out — buttons show but do nothingThe Mac is locked, or this device is read-onlyUnlock the Mac, or raise this device's level under the Paired Devices pane.
No push notifications arriveNotifications aren't enabled, or the sender is offlineEnable them in Alerts (under the More tab) and allow notifications when iOS asks; make sure the Mac (or its push relay) is online to send.
A device web page won't loadYour phone can't reach that device's networkGet on the same Wi-Fi as the device, or reach it over Tailscale; the in-app browser already trusts self-signed certificates, so a certificate warning is not the problem.

6.6When you can't reach the Mac

The app tries the addresses captured when you paired, in order: your home or office network first, then Tailscale, then a Cloudflare tunnel. If none answers, the Fleet tab's status dot shows offline. Run through the obvious causes in order. Is FrontierStack actually open on the Mac, with its control server switched on? Are you on the same Wi-Fi? If you are away from home, is Tailscale connected on both the phone and the Mac (or a subnet router), or has the Mac enabled a Cloudflare tunnel? A pull-to-refresh on the Fleet tab forces the app to retry every path. The Reached via line in Settings tells you which address is currently working, which is a quick way to confirm the link is alive.

TipFor reliable access away from home, install Tailscale on both the phone and the Mac (or run it on a router). With both on the same tailnet, everything — the Fleet tab, alerts and device pages — works as if you were sitting at home.

6.7Greyed-out controls and missing alerts

If you can see status but the Start/Stop buttons do nothing, the app isn't broken — it is telling you the action isn't permitted right now. Either the Mac is locked at its login window, in which case it won't act on a remote command until someone unlocks it, or this device's permission level is too low. Raise the level on the Mac under the Paired Devices pane, or pick up a device that already has the rights.

For alerts, remember the chain has two ends. The phone has to have notifications enabled — Enable notifications in Settings, and allow them when iOS prompts — and the Mac (or its push relay) has to be online to send them. If alerts simply stop arriving, the most common reason is that the Mac went to sleep or offline; wake it and confirm it is reachable from the Fleet tab.

6.8Where to go from here

That is the whole companion app: pair once from the Mac, watch your fleet from anywhere, act when your permission level allows, and keep the phone itself locked. You have a faithful, secure window onto everything FrontierStack runs — in your pocket.

For more, the in-app Help & Guide (Settings ▸ Help & Guide) mirrors this manual and is always current with your version of the app. The desktop app does the heavy lifting; its own manual covers every pane and service in depth — start at the FrontierStack manual. And whenever you want the latest news, downloads or support, visit frontierstack.app. Thank you for running your servers with FrontierStack.